PT-2004-1154 · Ibm · Aix
Published
2004-01-08
·
Updated
2017-07-11
·
CVE-2003-0696
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
AIX versions 5.1 through 5.2
Description
The issue concerns the
getipnodebyname() API, which fails to properly close sockets. This can be exploited by attackers to cause a denial of service through resource exhaustion.Recommendations
For AIX versions 5.1 and 5.2, consider restricting access to the
getipnodebyname() API until a proper fix is available. As a temporary workaround, implement measures to monitor and limit socket usage to prevent resource exhaustion.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aix